EP0807911A2

Client/server protocol for proving authenticity

Abstract

A protocol for establishing the authenticity of a client to a server in an electronic transaction by encrypting a certificate with a key known only to the client and the server. The trust of the server, if necessary, can be established by a public key protocol. The client generates and sends over a communications channel a message containing at least a part of a certificate encrypted with the server's public key or a secret session key. The server receives and processes the message to recover at least part of the certificate, verifies and accepts it as proof of the client's authenticity.

EP0807911A2, drawing sheet 1
Sheet 1 of 14

Term

Term ended

Projected expiry passed 12 May 2017, 9.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

97 claims: 8 independent, 89 dependent

  1. 1
    A method for establishing the authenticity of a client in a client-server electronic transaction where a server having a public key/private key pair and a certification authority's public key and a client having a certificate signed by the certification authority are coupled by a communications channel comprising,    the client, a) generating a secret session key, b) producing a time-varying value, c) concatenating one of the secret session key or the certificate with the time-varying value, d) encrypting the secret session key or the secret session key concatenated with said time-varying value with the server's public key to produce a first message, e) encrypting at least a part of the certificate or the certificate concatenated with the time-varying value with said secret session key to produce a second message, and f) sending the first and second messages to the server, where a decrypting operation by the server on the first message with the private key of the public key/private key pair provides the server with the secret session key, a decrypting operation on the second message with the secret session key provides the server with at least a part of the client's certificate, the decrypting operation with one of the keys provides the time-varying value, and a verifying operation on the time-varying value and a public key operation with the certification authority's public key and verifying operation on the client's certificate establish the authenticity of the client.
  2. 10
    A method for establishing the authenticity of a client in a client-server electronic transaction where a server and a client are coupled by a communications channel, comprising, establishing a client's trust in the server over the communications channel, the client having stored in a memory a certificate and the server's public key, and (a) generating in a processor, upon having established the trust in the server, a secret session key, encrypting the secret session key with the server's public key and sending the encrypted secret session key as a message to the server over the communications channel, and (b) encrypting at least a part of said certificate with said secret session key and sending the results of the encryption to the server over the communications channel, whereby decryption with the server's private key associated with the server's public key by the server yields the secret session key and decryption of the results by the server with the secret session key produces at least a part of the client's certificate which is proof of the client's authenticity.
  3. 28
    A smart card comprising a processor, a read only memory and an input/output port, said processor including means for producing a trusted server's public key, and means for executing a protocol stored in said memory for establishing the authenticity of the smart card to a trusted server and for generating a secret session key, said read only memory having stored therein a certificate for the smart card, said protocol including encrypting the secret session key with the trusted server's public key and sending the encrypted secret session key to the trusted server over the input/output port, said protocol further including encrypting at least a part of said certificate for the smart card with said secret session key and sending the encrypted certificate to the trusted server over the input/output port.
  4. 39
    A server having a protocol for interactively engaging with and verifying the authenticity of a client of limited computational capacity comprising, a memory storing a private key of the private key/public key pair of the server and a trusted certification authority's public key, a facility for generating time-varying values, a processor for performing the protocol, said protocol including, receiving and processing from said client a message including a session key encrypted with the server's public key and at least a part of the client's certificate encrypted with the session key, one of said session key and said at least a part of the client's certificate being concatenated with a time-varying value, said processing including performing a private key operation on the message with the server's private key to recover the session key, decrypting the message with the session key to recover at least part of the client's certificate, receiving the time-varying value from the message and checking it with the current time-varying value of the facility to see that the client's time-varying value is proper, performing a public key operation on the at least part of the client's certificate with the trusted certification authority's public key and verifying the client's certificate.
  5. 44
    A smart card comprising a processor, a read only memory, an input/output port, and a facility for producing a time-varying value, said processor including means for producing a server's public key and means for executing a protocol stored in said memory for establishing the authenticity of the smart card to a trusted server, said memory having stored therein a certificate for the smart card, said protocol including concatenating at least a part of the certificate with a time-varying value provided by said facility, encrypting the result of the concatenating with the server's public key to form a message and sending the message via the input/output port.
  6. 52
    A method for establishing the authenticity of a client in a client-server electronic transaction where a server having public key/private key pairs and a certification authority's public key and a client having a certificate signed by the certification authority are coupled by a communications channel comprising the client, producing a time-varying value, concatenating the time-varying value with at least part of said certificate, encrypting the concatenated result with the server's public key to produce a message, and sending the message to the server, the server, decrypting the message using the private key of the public key/private key pair recovers the time-varying value and at least part of the client's certificate, verifies the time-varying value and processes at least part of the certificate using the certification authority's public key and verifies it, establishing the authenticity of the client.
  7. 65
    A method for determining at a verifier whether a user is authorized to perform an operation, said method comprising the step of obtaining from said user a credential authorizing said user to perform said operation, wherein said credential includes a digital signature by a credential issuing authority;at least data essential to verify said credential is transmitted from said user to said verifier through an encrypted communications channel;and wherein the determination of authorization does not depend on an operation with a public key belonging to said user.
  8. 91
    A system for determining whether a user is authorized to perform an operation with a verifier, said system comprising:a user element for providing all or at least a part of the data included in a credential, said user element also providing data essential to verify the credential, said credential including at least a digital signature by a credential issuing authority;said user element having a protocol for engaging with the verifier and including a device which selects data for transmission to the verifier, said data selected by the device including at least data essential to verify the credential;an encrypted communication channel responsive to the device for transmitting data between the user element and the verifier, and the verifier including a protocol for determining whether the user is authorized to perform an operation wherein the determination does not depend on the transmission of a user's public key from the user element.